
By Byron V. Acohido
Security teams are being told they have hours to patch.
Related: AI agents have a Lord of the Flies problem
The warning has a real basis. In June, Anthropic’s frontier red team demonstrated an AI model building working exploits from freshly patched Firefox and Windows kernel vulnerabilities, one of them in 31 minutes. Meanwhile ZeroDayClock, widely cited across the security industry, put mean time-to-exploit near a single day and projected it falling to one hour by 2027.
Root Evidence went looking for evidence that attacker behavior had actually changed.
Its recently released Vulnpocalypse Report traced confirmed in-the-wild exploitation of published CVEs from January 2018 through July 15, 2026. Of 253,912 vulnerabilities published during that period, adversaries exploited 3,769, about 1.5 percent. For vulnerabilities exploited after a patch was available, the median defender window was 116 days so far in 2026, compared with 24 days in 2018.





